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SUBSCRIBER IDENTITY MODULE MOBILE STATION AND METHOD FOR PERFORMING A SMART CARD 
FUNCTION 

The present invention relates to a subscriber 
identity module as defined in the preamble of claim 1. 
5 Moreover, the invention relates to a mobile station as 
defined in the preamble of claim 5. The invention also 
relates to a procedure for applying a subscriber iden- 
tity module and a mobile station as defined in the 
preamble of claim 10. 

10 In prior art, a subscriber identity module is 

known that comprises a memory device, a data proces- 
sing device connected to it and an interface for con- 
nection to a mobile station. Further, in a known met- 
hod of communication between a subscriber identity mo- 

15 dule and a mobile station, the mobile station initia- 
tes the connection. The subscriber identity module as 
known at present cannot initiate communication with 
the mobile station. An example of such a system is the 
GSM system {GSM, Global System for Mobile Communica- 

2 0 tions) . Moreover, a subscriber identity module card is 

known in which a single physical card may contain se- 
veral independent subscriber identity modules. An 
example of such a system is a SIM card (SIM, subscri- 
ber identification module) used in the GSM system that 
25 has two processors on opposite sides of the card. In 
the GSM mobile telephone network, the SIM card is a 
component which, in addition to the subscriber's in- 
ternational telephone number, also contains other sto- 
red user-specific and network-specific data, such as 

3 0 the user's coded speed dialling numbers, a password to 

prevent misuse, and international codes of intercon- 
nected systems. A priority level for congestion situa- 
tions can also be defined for the card. With the 
double SIM card described above, the user gets two se- 
3 5 parate subscriber connections, i.e. the user may make 
private calls at his/her own cost and on-duty calls at 



WO 98/33343 



PCT/FI98/00080 



the cost of his/her employer. A circumstance characte- 
ristic of such a solution is that the two processors 
on the card are unable to communicate between themsel- 
ves. In other words, the solution described above ba- 
5 sically corresponds to a situation where two SIM cards 
are disposed on the same carrier. 

On the other hand, a smart card is known who- 
se structure mainly corresponds to the above -de scribed 
subscriber identity module. A smart card is generally 

10 used e.g. as an access card, a key or as a bank card. 
In prior art, many different types of physical inter- 
face between the smart card and the external world are 
known. The card may be e.g. in galvanic contact with 
the external world. There may also be a wireless con- 

15 nection between the card and the external world. In 
this case, bot the card and the card reader are provi- 
ded with coils, between which both information and po- 
wer needed for the functions of the card are transfer- 
red. Therefore, the card can communicate with the ex- 

2 0 ternal world at radio frequencies without a physical 

contact with a reader device. Examples of this type of 
cards are the remote -read cards used e.g. in buses. 

It is also known in prior art that the 
subscriber identity module, or SIM, may communicate 
25 with a mobile station and a physical transmission net- 
work over a standardised interface. The data on the 
SIM card can be changed via the air interface by 
transferring information to the card using short 
messages, e.g. SMS and USSD messages {SMS , Short 

3 0 Message Service; USSD, Unstructured Supplementary Ser- 

vice Data) . It is also possible to use a telecommuni- 
cation terminal to change the data on the SIM card. 

Further, many prior-art systems requiring 
user identification are based on a card identifying 
3 5 the user. Such systems include e.g. access control 
systems. Cards identifying the user are also used in 
various transactions in which the card indicates that 
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a payment has been remitted beforehand or registers 
the transaction as a credit transaction. Examples of 
such systems are remote -read bus tickets and credit 
cards issued by banks. In such systems, the updating 
5 of the cards is always done either by physically 
recharging the card with additional rights using a 
charger or by replacing an outdated disposable card 
with a new one. Another alternative is to update the 
reader, but this is only possible in the case of a li- 

10 mited number of users. 

A problem with these systems is that the user 
must carry several different cards used in different 
systems. When using different systems, the user always 
needs a certain card designed for the particular sys- 

15 tern. 

A further problem is that the various actions 
for updating of the cards, such as recharging the 
cards with money, changing the validity time, checking 
credit information and similar actions must always be 

2 0 carried out separately for each card at different 

points. For example, a money card is recharged at a 
bank, a credit card is updated on the premises of the 
commercial enterprise giving the credit, a bus ticket 
is updated at a kiosk, and so on. 
25 The object of the present invention is to 

produce a new type of subscriber identity module that 
makes it possible to combine several cards used in 
different systems . 

Another object of the invention is to produce 

3 0 a subscriber identity module that makes it possible to 

unify the use of different cards, in other words, a 
subscriber identity module that allows the information 
on cards of different systems to be updated in a cent- 
ralised manner and almost independently of location by 
35 using a mobile station. 

A further object of the invention is to pro- 
duce a mobile station that makes it possible to combi- 
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ne the functions of different smart cards and that can 
be used in more versatile ways and also for purposes 
other than its conventional function. 

A further object of the invention is produce 
5 a procedure that allows more diversified functions to 
be performed using a mobile station. 

In short, the object of the invention is to 
enable new diversified service combinations to be so 
implemented that they can be utilised via a data com- 
10 munication device, such as a mobile station. A feature 
characteristic of these service combinations is that a 
part of the series of actions is carried out in a sys- 
tem and/or application external to the data communica- 
tion system and the data communication device. 
15 As for the features characteristic of the in- 

vention, reference is made to the claims. 

The subscriber identity module of the inven- 
tion comprises a data processing device, which may be 
a very simple logic circuit or a more complex micro- 

2 0 processor. In addition, the module comprises a memory 

device connected to the data processing device. The 
memory device may be any known type of memory, such as 
ROM, RAM, EPROM or EE PROM . Furthermore, the subscriber 
identity module of the invention comprises a first da- 

25 ta transfer device, which is connected to the data 
processing device and provided with a first interface 
for data transfer between a mobile station (MS) and 
the subscriber identity module. The data transfer de- 
vice may be e.g. in galvanic contact with the mobile 

30 station. 

According to the invention, the subscriber 
identity module comprises a second data transfer devi- 
ce, which is connected to the data processing device 
and provided with a second interface, over which a 

3 5 connection for data transmission to a device and/or 

application other than a mobile station is set up. 
This other device and/or application may be any exter- 
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nal system provided with means for reading and/or wri- 
ting data over the second interface. The subscriber 
identity module may also comprise more than two data 
transfer devices and/or interfaces. 
5 In an embodiment of the present invention, 

the subscriber identity module comprises a reading and 
writing device connected to the data processing device 
via the second data transfer device. This reading and 
writing device may be a remote device as generally us- 

10 ed e.g. in smart cards, in which information and the 
power needed by the module is transferred via windings 
or an equivalent medium. On the other hand, the rea- 
ding and writing device may be an infrared operated 
device, in which the signalling takes place in the 

15 infrared wavelength range. 

The invention further relates to a mobile 
station comprising a subscriber identity module as 
described above. The mobile station may preferably 
comprise a remote device as described above, connected 

2 0 over an interface to the subscriber identity module. 

In this case, the subscriber identity module itself 
may only contain a second data transfer device with a 
second interface, over which the desired connection to 
the remote device in the mobile station is set up. 
25 In the procedure of the invention for perfor- 

ming a smart card function using a mobile station as 
described above, a connection between the subscriber 
identity module and a first external system is first 
established. This connection setup initialises the 

3 0 smart card transaction and it comprises exchange of 

information relating to the subscriber identity module 
and the external system. After this, the user is re- 
quested to give his/her approval for the execution of 
the smart card transaction. The request can be presen- 
3 5 ted e.g. via the display of the mobile station or via 
a sound signal or a corresponding action. Finally, the 
first external system is informed of the user's appro- 
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val . On the other hand, in an embodiment of the inven- 
tion, in addition to or instead of the user 1 s appro- 
val, it is possible to request the approval of a se- 
cond external system for the execution of the smart 
5 card transaction. 

In a preferred embodiment of the procedure, 
predetermined information for the smart card transac- 
tion is stored in the subscriber identity module and 
the information is updated based on the smart card 
10 transaction under control of the first system. Such 
information may relate e.g. to the recharging of a 
rechargeable money card, in which the amount of money 
stored on the card is reduced on the basis of transac- 
tions . 

15 The connection to the second external system 

is preferably established via a mobile communication 
network. The connection can be set up using short 
messages, such as SMS and/or USSD messages. 

As compared with prior art, the present in- 

2 0 vent ion affords the advantage that the subscriber 

identity module of the invention makes it possible to 
combine several cards used in different systems. Furt- 
her, the invention makes it possible to unify the use 
of different cards included in the subscriber identity 
25 module, in other words, it makes it possible to update 
the information on cards of different systems in a 
centralised manner and almost independently of locati- 
on by using a mobile station. In addition, the inven- 
tion allows various smart card services to be used 

3 0 with a single card. 

In addition, the invention makes it possible 
to produce a mobile station by means of which the 
functions of different smart cards can be used and 
which can be used in more versatile ways and also for 
35 other purposes besides its conventional function. As a 
further advantage, the procedure of the invention pro- 
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vides a handy way to implement the previously slow and 
difficult smart card functions. 

In the following, the invention will be 
described by the aid of some examples of its embodi- 
5 ments by referring to the attached drawing, in which 

Fig. 1 presents a subscriber identity module 
according to the invention; 

Fig. 2 presents a diagram representing a mo- 
bile station according to the invention; 
10 Fig. 3 represents the signalling in a prefer- 

red embodiment of the present invention; and 

Fig. 4a - 4c are flow diagrams representing 
certain preferred embodiments of the procedure of the 
invention. 

15 The subscriber identity module SIM presented 

in Fig. 1 comprises a processor circuit 1 which cont- 
rols all functions of the module. Moreover, the module 
comprises a memory circuit 2, which is connected to 
the processor circuit and contains all the software 

2 0 needed in the module, such as the operating system, 
data transfer protocols for different interfaces, and 
other programmes required. In addition, the module 
comprises a first data transfer device 3, which inclu- 
des the functions for the establishment of a first in- 

2 5 terface RP1 and is used to set up a connection to a 

mobile station MS. Furthermore, the module comprises a 
second data transfer device 4, which comprises the 
functions for the establishment of a second interface 
RP2 and is used to set up a connection to a second 

3 0 system, e.g. to a remote- read card connected to the 

subscriber identity module. 

The subscriber identity module presented in 
Fig. 1 also has other preferred embodiments, which are 
not actually shown in the figure but which are obvious 
35 to the skilled person from Fig. 1. One embodiment is a 
module that contains several processor circuits acces- 
sing a common memory area. In this case, one processor 
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takes care of one interface to the external world. In 
such an arrangement, it is necessary to ensure that 
when one processor is writing information to the com- 
mon memory area, the others cannot read it simulta- 
5 neously from the same memory area. A mechanism of this 
type is known e.g. from database solutions. 

Another embodiment is a card with a single 
processor whose capacity is shared between several 
processes. In this case, one process takes care of da- 

10 ta communication over one interface. Such a solution 
is known e.g. from the computer world. For example, 
the UNIX operating system can work with a single pro- 
cessor by utilising the processor's multitasking capa- 
bility. This is the way the card would function in 

15 this embodiment. A further possibility is to use a hy- 
brid solution comprising more than one processor but 
having a number of interfaces that is not the same as 
the number of processors. 

The GSM mobile station MS represented by the 

2 0 diagram in Fig. 2 comprises a SIM 1 that has been 

slightly modified from the subscriber identity module 
SIM in Fig. 1. In addition to a module according to 
Fig. 1, SIM 1 comprises a remote-read card 5. The remo- 
te-read card 5 is connected via a wireless link to a 
25 first system Jl , in which a first application SI is 
operated. The subscriber identity module SIM is con- 
nected to the remote -read card via a second interface 
RP2 . The mobile station MS further comprises an infra- 
red device 6 comprising both an infrared transmitter 8 

3 0 and an infrared receiver 9. The infrared device can 

also be used as a bar code reader, and the information 
read from an application S2 operated in a second sys- 
tem J2 can be transferred over a third interface RP3 
into the subscriber identity module for further pro- 
3 5 cessing. The mobile station MS further comprises a 
matching module 7, which is used to establish a con- 
nection to the subscriber identity module SIM over the 
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first interface. In addition, as shown in Fig. 2, the 
mobile station communicates over a wireless connection 
with a GSM system and an application/applications S3 
operated in it . 
5 Fig. 3 represents the signalling between dif- 

ferent parts of the assembly in a preferred embodiment 
of the present invention. This series of actions is 
also represented by the flow chart in Fig. 4a. 

In Fig. 3, the server 10 is a computer com- 

10 prised in a physical transmission medium, such as a 
GSM network, and it is capable of communicating in the 
manner required by the application in the subscriber 
identity module card. An external system Jl, e.g. a 
remote reader, sends a debiting message, containing 

15 information about a sum to be debited, to an applica- 
tion in the subscriber identity module SIM, block 21. 
The application in the subscriber identity module de- 
vice SIM recognises the message as one sent by an ex- 
ternal device and forwards it via a physical interfa- 

2 0 ce, e.g. a GSM network, as a short message, such as an 

SMS or USSD message, to a suitable server 10 in the 
GSM network. Before forwarding the message, block 22, 
the application in the subscriber identity module SIM 
may require an approval of the function from the user. 
25 If no approval is obtained, the transaction is termi- 
nated, block 23. The message received from the reader 
Jl must contain an identifier informing the applicati- 
on in the subscriber identity module SIM that a res- 
ponse to the message is expected. The server 10 in 

3 0 turn must contain a programme that is able to inter- 

pret the messages arriving from the subscriber identi- 
ty module SIM and respond to them appropriately. An 
appropriate response may involve e.g. verification of 
the creditworthiness of the subscriber identity module 
35 that sent the SMS or USSD message, and the granting or 
turning down of credit. A response indicating granting 
or rejection of credit is sent to the subscriber iden- 
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tity module in the form of an SMS or USSD or other 
short message, which is identified by the module app- 
lication as a response to a message sent out shortly 
before, and forwarded to an external reader Jl, block 
5 24. The arrival of a response in the reader Jl must be 
indicated e.g. by a sound signal. If an affirmative 
answer is received, the reader Jl responds by printing 
a receipt for the payment. If the answer is negative, 
the reader Jl responds by announcing that the payment 

10 could not be made, block 25. 

An SMS sent by the subscriber identity module 
SIM must contain a code (e.g. IMSI in the GSM system) 
identifying the subscriber identity module, the amount 
debited as well as other information relating to the 

15 debiting, such as the date and the place and time of 
purchase. Moreover, the system must contain encryption 
and authentication mechanisms. 

Referring to Fig. 4b, if the subscriber iden- 
tity module card in the transaction illustrated by the 

2 0 figure is a so-called prepaid card, no debiting will 

have to be done from the server 10. Instead, money is 
first loaded into the module SIM e.g. using a SMS 
message, block 31. The procedure continues by first 
reading into the subscriber identity module SIM the 
25 sum to be debited, block 32, and then debiting the 
customer by decreasing (block 33) his/her payment 
tickets created beforehand on the card SIM. Finally, 
the seller's system Jl is informed of the remittance. 

Correspondingly, in a third example , repre- 

3 0 sented by the flow diagram in Fig. 4c and relating to 

access control, the signalling is based on the use of 
a GSM network as a physical transmission link by ma- 
king use of short messages, such as SMS or USSD 
messages to transmit information. The user requests 
3 5 access by sending either an SMS, USSD or other short 
message, block 41. To be able to make the request, the 
subscriber identity module card SIM must contain an 
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application that knows how to ask both the user and 
the server for the right things. In GSM cards, this 
could be implemented using an Application Toolkit con- 
sistent with the GSM standards. The server must per- 
5 form the required actions to allow or deny access and, 
if necessary, to debit the user for the permission, in 
which case the user's creditworthiness must be veri- 
fied or tickets decreased on a prepaid card. As in the 
previous example, in this case, too, the server recei- 

10 ves information indicating that a response to the 
message is expected. An external reader verifies the 
user's right of access by asking the subscriber iden- 
tity card about the right of access. If the card has 
the right of access, the reader will indicate this by 

15 giving a sound signal or by opening the door. In the 
case of a card with a right of access granted for a 
certain period, the right can be removed from the card 
by sending a new SMS, USSD or other short message and 
deleting the field indicating right of access. 

2 0 Another arrangement for verifying the right 

of access of the card is that the information regar- 
ding right of access is located in the reader instead 
of on the card, and a server 10 in the transmission 
network sends the reader Jl information regarding the 

2 5 right of access of each card at certain intervals. In 

this case, the reader Jl only asks the card SIM for an 
identification number, block 42, and compares it with 
its own data to decide about the user's right of ac- 
cess, block 43. In the case of rights granted for a 

3 0 certain period, the right of access expires when the 

card number is no longer updated in the reader as an 
allowed number entitled to access. In the case of the 
solution described, the server could be provided with 
a timer whose triggering would result in removing out- 
35 dated card numbers indicating right of access. 

To sum up, let it be stated that in practice 
the actions described above are realised by briefly 
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12 

exposing a telephone to a remote reader and verifying 
the transaction via the user interface of the telepho- 
ne, whereupon the transaction is recorded in the remo- 
te reader. Depending on the nature of the transaction, 
5 either a data link is needed between the remote reader 
and the data system or the files in the remote reader 
are transferred into the data system e.g. at the end 
of each day. Thus, a user having a mobile station with 
a suitable card in it will be able to carry out vari- 
10 ous smart card functions using only his/her telephone. 

The invention is not restricted to the 
examples of its embodiments described above, but many 
variations are possible within the scope of the inven- 
tive idea defined by the claims. 
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CLAIMS 

1. Subscriber identity module (SIM) , compri- 
sing a data processing device (1) , a memory device (2) 
connected to the data processing device, and a first 
5 data transfer device (3), which is connected to the 
data processing device and provided with a first in- 
terface (RP1) for data transfer between a mobile sta- 
tion (MS) and the subscriber identity module, cha- 
racterised in that the subscriber identity mo- 

10 dule (SIM) comprises a second data transfer device 
(4) , which is connected to the data processing device 
(1) and provided with a second interface (RP2) , over 
which a data transfer connection to a device and/or 
application other than a mobile station is set up. 

15 2 . Subscriber identity module as defined in 

claim 1, characterised in that the subscriber 
identity module (SIM) comprises a reading and writing 
device (5) connected to the data processing device (1) 
via the second data transfer device (4) . 

20 3 . Subscriber identity module as defined in 

claim 1 or 2, characterised in that the rea- 
ding and writing device (5) is a remote device. 

4. Subscriber identity module as defined in 
any one of claims 1 - 3, characterised in 

2 5 that the reading and writing device (5) is an infrared 

device. 

5. Mobile station comprising a subscriber 
identity module that comprises a data processing devi- 
ce (1) , a memory device (2) connected to the data pro- 

3 0 cessing device, and a first data transfer device (3) , 

which is connected to the data processing device and 
provided with a first interface for data transfer bet- 
ween the mobile station (MS) and the subscriber iden- 
tity module, characterised in that the 
3 5 subscriber identity module (SIM) comprises a second 
data transfer device (4) , which is connected to the 
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data processing device (1) and provided with a second 
interface, a data transfer connection being set up 
over the second interface to a device and/or applica- 
tion other than a mobile station. 
5 6. Mobile station as defined in claim 5, 

characterised in that the subscriber identity 
module (SIM) comprises a reading and writing device 
(5) connected to the data processing device (1) via 
the second data transfer device (4) . 
10 7. Mobile station as defined in claim 5 or 6 , 

characterised in that the reading and writing 
device (5) is a remote device. 

8 . Subscriber identity module as defined in 
any one of claims 5 - 7 , characterised in 

15 that the reading device (5) is an infrared device. 

9. Mobile station as defined in any one of 
claims 5 - 7, characterised in that the mobi- 
le station comprises a remote device (6) connected 
over a third interface (RP3) to the subscriber identi- 

2 0 ty module (SIM) . 

10. Procedure for performing a smart card 
function using a mobile station as defined in claim 5, 
characterised in that 

a connection between the subscriber identity 
25 module and a first external system is established; 

the user is requested to give his/her appro- 
val for the execution of the smart card function; and 

the first external system is informed of the 
user 1 s approval . 
30 11. Procedure as defined in claim 10, cha- 

racterised in that a second external system is 
requested to give its approval for the execution of 
the smart card function. 

12. Procedure as defined in claim 10 or 11, 
35 characterised in that predetermined informa- 
tion for the smart card function is stored in the 
subscriber identity module and the information is up- 
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dated based on the smart card function under control 
of the first system. 

13 . Procedure as defined in any one of claims 
10 - 12, characterised in that the connection 

5 to the second external system is established via a mo- 
bile communication network. 

14. Procedure as defined in claim 13, cha- 
racterised in that short messages, preferably 
SMS and/or USSD messages, and/or other message 

10 transmission methods defined in the GSM standard are 
used for the transmission of information in the mobile 
communication network. 
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